You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot应用SSL连接Kafka集群失败,抛出SslAuthenticationException求助

Troubleshooting SSL Authentication Failure with Spring Boot & Kafka

Hey there, let's dig into this SSL authentication issue you're hitting. That SslAuthenticationException paired with the "no record information is available" error from Spring Kafka's error handler is a clear clue—the root problem is your app can't successfully complete the SSL handshake with the Kafka cluster, and the default error handler doesn't know how to recover from this since there's no Kafka record involved yet.

Let's walk through step-by-step checks and fixes:

1. Verify Certificate File Access & Permissions

The most common culprit here is that your app can't actually read the keystore/truststore files:

  • Double-check the paths in your config: file:/var/ssl/private/client.truststore.jks and file:/var/ssl/private/client.keystore.jks. Are these absolute paths correct? Does the file exist at those locations?
  • Check filesystem permissions: The user running your Spring Boot app needs read access to both the /var/ssl/private directory and the JKS files inside it. You can test this with a simple command like sudo -u <your-app-user> cat /var/ssl/private/client.truststore.jks—if it outputs binary data, access is okay; if it throws a permission error, fix the directory/file permissions.

2. Validate Certificate Content & Configuration

Next, ensure your certificates are valid and correctly configured:

  • Use the keytool command to inspect your keystore and truststore:
    # Check keystore (client cert + private key)
    keytool -list -v -keystore /var/ssl/private/client.keystore.jks
    # Check truststore (Kafka cluster's CA cert)
    keytool -list -v -keystore /var/ssl/private/client.truststore.jks
    
    • Confirm the truststore contains the CA certificate that signed the Kafka brokers' SSL certificates. Without this, your app can't trust the broker's identity.
    • Confirm the keystore has a valid client certificate and private key. Check the "Valid from" and "Valid until" dates to make sure no certificates are expired.
    • Double-check that spring.kafka.ssl.key-password matches the password for your client's private key (this can be different from the keystore password—easy to mix up!).

3. Align SSL Settings with Kafka Broker Configuration

Your app's SSL config needs to match what the Kafka cluster expects:

  • If the Kafka brokers have ssl.client.auth=required set (meaning they demand client certificates), ensure the broker's truststore includes your client's CA certificate (or your client's certificate directly).
  • Explicitly set the SSL protocol to match the broker's supported version (TLSv1.2 is widely used and secure):
    spring.kafka.ssl.protocol=TLSv1.2
    spring.kafka.ssl.enabled-protocols=TLSv1.2
    
  • If you're hitting cipher suite mismatches, you can specify compatible suites (check your Kafka broker's config for allowed ciphers):
    spring.kafka.ssl.cipher-suites=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
    

4. Fix the Error Handler Behavior (Temporary Workaround)

The IllegalStateException about the error handler is a secondary issue—once you fix the SSL auth, this will go away. But if you want to handle this cleanly while troubleshooting, you can define a custom error handler:

import org.apache.kafka.common.errors.SslAuthenticationException;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import org.springframework.kafka.listener.KafkaListenerErrorHandler;
import org.springframework.messaging.Message;
import org.springframework.stereotype.Component;

@Component("customSslErrorHandler")
public class CustomSslErrorHandler implements KafkaListenerErrorHandler {

    private static final Logger log = LoggerFactory.getLogger(CustomSslErrorHandler.class);

    @Override
    public Object handleError(Message<?> message, Exception exception) throws Exception {
        if (exception.getCause() instanceof SslAuthenticationException) {
            log.error("Fatal SSL authentication failure—cannot connect to Kafka cluster. Check certificates and config.", exception);
            // You could trigger an alert, stop the consumer container, or take other action here
            throw new IllegalStateException("SSL auth failed, cannot proceed", exception);
        }
        // Let other errors fall through to the default handler
        throw exception;
    }
}

Then reference it in your @KafkaListener:

@KafkaListener(topics = "your-topic", errorHandler = "customSslErrorHandler")

5. Enable SSL Debug Logs for Deep Diving

If you're still stuck, turn on SSL debug logs to see exactly where the handshake is failing. Add this JVM argument when starting your app:

-Djavax.net.debug=ssl:handshake:verbose

The logs will show every step of the SSL handshake—look for lines like certificate not trusted or unable to load private key to pinpoint the exact issue.


内容的提问来源于stack exchange,提问作者Akshay Ubale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:53:07